Health Care Organizations Comment on Proposed Modifications to HIPAA Privacy, Security and Enforcement Rules
Time 3 Minute Read

The Department of Health and Human Services (“HHS”) received numerous comments on its proposed modifications to the Health Insurance Portability and Accountability Act Privacy, Security and Enforcement Rules, which were issued on July 8, 2010.  Some highlights from the comments are outlined below.

Enforcement Rule

The American Hospital Association (“AHA”) suggested that HHS should continue to require the Secretary of HHS to attempt to resolve a complaint or compliance review through informal means, instead of making the informal resolution process optional.  According to the AHA, making “resolution via informal means optional, regardless of the perceived level of culpability of a particular entity” would not be appropriate or effective.  The Coalition for Patient Privacy, on the other hand, recommended stricter enforcement so that “the only category of violators that should not be penalized with fines are those who despite due diligence could not discover the violation, who reported the violation immediately when discovered, and fully corrected the problems within 30 days of discovery.”

Privacy Rule

The AHA requested that HHS “consider modifying the Privacy Rule to make clear which provisions are directly applicable to business associates and to specify business associates’ compliance obligations associated with each of these provisions” in order to “provide greater clarity and better facilitate compliance” with the Privacy Rule.  The Association of American Medical Colleges recommended that the exception to the rule prohibiting the sale of protected health information (“PHI”) for research purposes be expanded to included PHI that is provided to a data registry for the benefit of providing researchers with access to a larger pool of data for their research.

Security Rule

The American Health Information Management Association expressed concern that the modifications to the Security Rule “appear to suggest that Covered Entities do not need to make as many specific requirements of a Business Associate as in the pre-HITECH agreements because the Business Associate becomes directly subject to HIPAA.”  The Coalition for Patient Privacy went further and recommended that HHS require all business associates and covered entities to “undergo meaningful and comprehensive security and privacy audits annually, to establish and prove that their methods of operation do in fact safeguard patient information.”

HHS will accept or reject the submitted comments to the modifications to the HIPAA Rules and decide whether to incorporate them into the Final Rule, which is expected to be published by the end of 2010.  Please check back with Hunton & Williams’ Privacy and Information Security Law for further developments on this topic.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 2 Minute Read

The New York Office of the Attorney General recently reached a $500,000 settlement with a New York orthopedics practice for allegedly failing to protect patient and employee information in light of a 2023 data breach.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page